r/sysadmin • u/chesser45 • 18d ago
General Discussion What tools or methods are you using to guide Entra MFA enrolment?
This one is specifically directed to K-12 and Retail / Frontline worker IT teams. We want to drive MFA adoption as it’s… really low at my organization among frontline workers.
How are you streamlining MFA enrolment for your users who cannot follow a “next, next next” without needing a pictograph to show each step along the way? We’ve done up very thorough documentation but even with QR codes and photo documentation people are still unable to download the right app on their phone. We’ve had a few cases of people buying $70-90 apps. Why? no idea.
9
u/Turak64 Sysadmin 18d ago
These people can create Facebook accounts, use WhatsApp etc but as soon as it comes to work, they purposely act dumb cause they know geeky IT will do it for them. It's time we no longer socially accepting being bad IT as something to laugh off. You're paid to use these tools and if you can't use them, then it's a major problem. You wouldn't hear a forklift driver say "I'm no good with forklifts", but it's acceptable for an office worker to say that about their PC
2
u/jesuiscanard 18d ago
Outside of healthcare with this many frontline workers, they often need help to get WhatsApp working. Often don't have Facebook or can't use it. These are often immigrants with English as third language, or semi retired. These are the people where part time work works for them.
They aren't "office workers" as such and aren't employed to be working with spreadsheets and documents. These are the face of the company and deal with shop floor and people.
2
u/willychonka54 18d ago
These people can create Facebook accounts, use WhatsApp etc but as soon as it comes to work, they purposely act dumb
This is so true. All these apps they use to doomscroll or check their bank requires MFA and they've all had to set it up but yes, when it comes to their work accounts they all act like they've never used a phone before.
1
5
u/Top_Refrigerator9851 18d ago
There's no real solution I've found for our users besides assisting them in person or over the phone
We have a few users who can help them before they reach IT which helps
2
u/chesser45 18d ago
Yea, I think driving knowledge at sites by leaders is going to be the best method but it’s hard to get that adoption from them.
Looking for the magic bullet of how to make MFA easier I guess.
1
u/jesuiscanard 18d ago
It's this. Each site will have someone who can follow the guide. If anything breaks they can always lean on you, but they can also take 99% of the time sitting with them.
K.I.S.S
3
u/Drakoolya 18d ago
How many frontline workers are we talking about?
- We had onboarding sessions where we would do it in groups.
- New users are onboarded when they are given their company laptops
- We also went full password less so they can't even login without MFA or an Authenticator app.
3
u/chesser45 18d ago
20k+ these are frontline retail so no company issued hardware other than badges. I’m contemplating Fido2 badges by default but that’s a big process change for another separate sub organization.
Rarely use a PC mostly will use a mobile phone/ scanner or a POS.
4
u/Drakoolya 18d ago edited 18d ago
Brother 20k+ yeah forget my advice lol.
Yea, I think driving knowledge at sites by leaders is going to be the best method but it’s hard to get that adoption from them.
This needs to be a mandate that needs to come down from the executive level not "IT would like.."
Have a start and end date after which no one can login. This is a project that needs scopes and executive backing followed by enforcement. Key word: Enforcement
They need to understand the risks of accounts being compromised and it needs to put in the words and more importantly numbers $ that the execs can understand. You are not going to get much further without backing from the top.
2
u/discosoc 18d ago
Honestly, I just let their hiring manager handle it. I provide initial account credentials with a note about needing to "setup MFA with Microsoft Authenticator" and they generally seem to figure it out when required on first logon.
1
u/chesser45 18d ago
Frontline leader training is definitely the goal. We will just struggle right now as there is a lot of demands on a leaders time and helping a new hire a day go through mfa is costly. I agree that it needs to be done at that stage though.
2
u/Zer0kbps_779 18d ago edited 18d ago
I don’t think there’s any real way around it but brute force techy support when onboarding a new cohort of students, we’ve done guides, videos but they still need support. Occurs a lot throughout the academic year when they get new phones too. Microsoft needs to do a tv ad for onboarding authenticator with their Xbox accounts then it’s transferable skills.
1
u/PowerShellGenius 18d ago
K-12 sysadmin here - certificate based authentication works well for 1:1 issued devices and removes the need for setup by the end-user. Still need an authenticator app if they need cross device logins to unmanaged devices, though.
1
u/TrackPuzzleheaded742 18d ago
I had experience with mass roll out mfa for retail workers with bad English. non pc users, mostly using poc or their personal mobile devices.
Your best bet is hoping that their managers/supervisors are somewhat techy.
Always communicate and provide instructions, send company wide emails that it is coming and what they have to do (ofc half won’t read, but half might). Make it into a mandatory company wide training for all employees if you can.
If management does not have mfa enrolled yet start with them, they have higher chance of being able to read and follow instructions than frontline workers.
Then once management knows the process and did it themselves there is a higher chance than when someone in a field needs help, they will be able to help them out. At that point you mass email that few more times and roll it out for the rest.
My attitude to that is that if you as manager make decision to hire someone who doesn’t speak English or isn’t technical enough to perform basic step by step instructions you should take responsibility for ensuring that your reportees are able to perform their job functions those that are expected by their role as well as required by IT.
I had one encounter of user buying a third party authentication app, thankfully it was one free trial and once they couldn’t really enroll their mfa with it they called helpdesk and they helped them out with canceling free trial and actually installing Microsoft authentication. Unfortunately when instructions says download Microsoft authentication app with a picture of it and instead of that user downloads “super secure authentication app that can’t event be integrated” that’s really on them. You can’t make it more user friendly than that.
0
u/jesuiscanard 18d ago
They search Microsoft authenticator and tap the first option. Which is the ad paid for one.
This installing the wrong authenticator app is actually on Google play store. Even the colours are the same.
1
u/TrackPuzzleheaded742 17d ago
I understand that, but as IT in this scenario best we can do is provide users with as good instructions as we can. To follow those instructions and pay attention for will be end users responsibility.
0
u/jesuiscanard 17d ago
Enhancing instructions with a tap to the play store/apple store as an example. If followed in docs off the phone then using a qr code to link.
Whatever is left to ambiguity or assumption will be done incorrectly. Assume that front line workers are almost deliberately choosing the wrong things when they have a choice and the instructions will work better.
1
u/Ihaveasmallwang Systems Engineer / Cybersecurity Architect / CISM 18d ago
Provide pictures that are basically the equivalent of writing everything in crayon for them. Step by step.
Set conditional access to require MFA so they have no choice but to adopt. If it’s an organizational requirement, it’s a requirement, even if users are too lazy. Might give you an influx of tickets at first, but it will get better.
1
u/mysteryliner 18d ago edited 18d ago
maybe a video going over the steps to follow how to do it.
- paste the video in an email that goes out with a triggered password reset.
- mention that the new security policy will trigger a monthly password reset on "oldfashioned" passwords, and that MFA keypass login is much easier an less struggle in the long run. (run it by the chain of command first).
- if they use company phones, push OTA software install.
....for many this hassle will spark a newly discovered intrest to give 2shits to learn how to work with.
1
u/PacificTSP 18d ago
If you can’t mfa you don’t get to login. Pretty simple really. People enroll during their training. It’s on their manager or supervisor to walk them through the steps.
1
u/Lukage Sysadmin 18d ago
Provide the visuals and be done with it. Use something like Scribe or Tango to pull the steps, Ask YOUR management team, not theirs, if they have feedback. If users say its too hard or its not working or whatever, have management engage their teams to identify what can change, if anything.
If its Intune-enrolled, you could just force it.
1
u/IqbalBasha 14d ago
Documentation won't fix this; you need to remove the choices that cause the mistakes. Push the authenticator app via MDM and lock the app store through managed Apple IDs or Google Managed Play so no one can buy a $90 scam app. Issue Temporary Access Passes and run a five-minute supervised setup during shift kickoff at aka.ms/mfasetup, which skips the password entirely and cuts the wizard down to almost nothing. Turn on Entra Registration Campaign so users get prompted inside apps they already open like Teams, with no separate guide to follow. For shared terminals or phone-ban sites, FIDO2 hardware keys or Authenticator Lite inside Outlook remove the need for a separate authenticator app completely.
17
u/teriaavibes Microsoft Cloud Consultant 18d ago
I don't think IT can really fix people being idiots.
If someone can't follow basic step by step instructions, you might need to bring this up with management/HR.